Skip to content

Open nowPosted 47 days ago

Security Architect

Workable (global search)108,016 open roles

Where
London, England, United Kingdom
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSecurity ArchitectWorkable (global search) · London, England, United Kingdom
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Workable (global search)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.9% of postings close within 7 days. Measured by our own scanner across the market. Workable (global search) postings stay open a median of 7 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 7.9%7 days
  4. 14.9%14 days
  5. 34.0%30 days
This job: posted 47 days ago

Workable (global search) median: 7 days open

The posting

About Indra Group UK & Ireland

Indra is a leading global technology and consulting company, and a trusted technological partner for the core business operations of its clients worldwide. It stands at the forefront of key sectors including Transport, Defence, Air Traffic Management and Space, alongside advanced Information Technology services delivered through Minsait, and cutting-edge capabilities in Sovereign AI, Cybersecurity, and Cyberdefence via IndraMind.

The company’s business model is built around a comprehensive portfolio of proprietary products, combining strong innovation with a high-value focus for customers.

With more than 2,500 projects implemented across 50 countries and over 100 cities, Indra is a global benchmark in innovative transportation and mobility solutions. It is recognised as one of the world’s top three companies in public transportation management systems. Indra’s technology supports the daily journeys of over 78 million people, helping to reduce more than 10 million tonnes of CO₂ emissions annually, and helping save nearly 3,000 lives through improved traffic management and road safety.

Indra Group is paving the way to a more secure and better-connected future through innovative solutions, trusted relationships and the very best talent. Sustainability sits at the heart of its strategy and culture, driving efforts to address current and future social and environmental challenges.

In the 2024 financial year, Indra achieved revenues of €5.5 billion, over 60,000 professionals, maintained a local presence in 46 countries, and operated across more than 140 countries worldwide.

As the technological partner for its customers’ key operations, Indra is at the core of their business, and Indra’s four values guide everything we do:

Innovation - Our capacity for innovation, cutting-edge solutions, and specialised team of professionals enables us to drive a safer, more connected future through technology.

Trust - We work with strength, commitment, and reliability, delivering quality solutions to build trust with customers, employees, partners, investors, and society.

Connection - We harness the power of collaboration, connect ideas and solutions, and adapt to our customers’ needs, supporting them on the path to a better future.

Foresight - We anticipate future needs to make the world safer and more connected, transforming our experience and knowledge into solutions for a better tomorrow.

About the Project

Transport for London (TfL) has awarded Indra a long-term contract to operate, develop, enhance and expand ticketing and access control systems across London’s transport network through to 2034, with extension options to 2039.

This programme covers the maintenance, operation and evolution of a large-scale, complex ecosystem, including turnstiles, validators, ticket machines, sales terminals, back-office systems, payment gateways, IT infrastructure and cybersecurity that supports over 8.6 million daily journeys.

Therefore, Indra will become TfL’s strategic technology partner to guarantee the operation and evolution of the world’s largest and most sophisticated ticketing system. Following a transition period of approximately two years, Indra will serve as the sole provider across the network that includes more than 8,500 buses, nearly 400 Underground stations, around 300 rail stations (Overground, DLR, Elizabeth Line and suburban services), 4,000 Oyster Card outlets, seven customer service centres, and 24 river boat boarding points.

Drawing on over 30 years of experience in urban public transport solutions, Indra will manage and evolve all aspects of the system. The project also envisages, in partnership with TfL, the implementation of new technologies to develop the system, make it more efficient and automate key processes; in short, to jointly create the next generation of the ticketing system for London.

Role overview

The Security Architect is responsible for defining, guiding, and assuring the implementation of security architecture and cyber resilience control across a range of systems, platforms, and services. This role provides strategic and technical security expertise to support the design, development, and delivery solutions, working closely with engineering teams, project stakeholders, and business units.

Key Responsibilities

  • Support the definition and integration of security requirements within projects, ensuring alignment with business needs and industry best practices.
  • Provide security architecture guidance for the design and evolution of cloud services, applications, back-office systems, and infrastructure solutions.
  • Contribute to the assessment and management of security risks, supporting activities such as risk analysis, impact assessments, and audits when required.
  • Collaborate with multidisciplinary teams (e.g. DevOps, system engineering, development, and project management) to promote secure-by-design principles across all phases of delivery.
  • Advise on the implementation of appropriate security controls (technical, procedural, and organisational) to ensure the protection of systems and data.
  • Support governance activities, including participation in design reviews, project checkpoints, and change management processes from a security perspective.
  • Promote best practices and continuous improvement in information security, contributing to the adoption of standards, frameworks, and emerging technologies.
  • Ensure that security considerations are appropriately documented and communicated to relevant stakeholders.
  • Support the definition of processes that enable secure system operation, maintenance, and service transition.
  • Ensure compliance with organisational policies, standards, and applicable regulatory requirements.

Working model:

  • First 3 months: 2 days onsite per week
  • Thereafter: fully remote with a maximum of 0–1 day onsite (as required)

Requirements

Minimum Job Requirements:

Qualifications

Core Requirements

  • Academic background or equivalent professional experience in a relevant discipline
  • Professional certification in Information Security (e.g. CISSP, CISM, CISA, CCSP or equivalent)
  • Ability to operate in environments requiring mobility, where applicable

Additional Assets

  • Technical degree in fields such as Computer Science, Engineering, Mathematics or similar
  • Certifications related to security architecture, privacy or governance frameworks
  • Familiarity with recognised methodologies or best practices (e.g. IT service management, project frameworks)
  • Vendor or cloud-related certifications in security or infrastructure

Experience & Technical Capabilities

Key Experience

  • Proven track record in defining and implementing security architectures or contributing to security design at system or enterprise level
  • Experience working across the full system or software lifecycle, including secure development and integration practices
  • Exposure to security governance, risk management, and compliance activities within complex environments
  • Solid understanding of enterprise IT ecosystems, including infrastructure, networking and systems

Technical Knowledge

  • Familiarity with commonly adopted security frameworks, standards, and regulations (e.g. ISO 27001, NIST, data protection regulations)
  • Understanding of network protocols, system architectures and core infrastructure components
  • Awareness of modern approaches such as DevSecOps and secure-by-design principles

Additional Knowledge (Desirable)

  • Experience working with cloud platforms and their associated security models (e.g. Azure, AWS, GCP)
  • Knowledge of specialised domains such as application security, identity and access management, or cryptography
  • Exposure to regulated environments, audit processes, or industry-specific compliance standards
  • Familiarity with security tools and technologies used for monitoring, testing, and protection (e.g. SIEM, vulnerability management, endpoint security)
  • Understanding of development environments, tooling, and security testing practices
  • Awareness of quality standards and structured assurance processes

Benefits

  • Holidays: 25 days per annum + 8 days bank holidays (options to buy/sell days).
  • Pension – 4% employee and 4% employer.
  • Private medical insurance (including dental & optical).
  • Life assurance.
  • Income protection.
  • Employee assistance programs.
  • Flexible/remote working options.
  • Charitable initiatives.
  • Social events (formal & informal).
  • Learning and development programs.
  • Innovative & collaborative work environment.

Indra is an equal employment opportunity employer. Applicants are considered without regard to race, colour, religion, sex, sexual orientation, gender identity, origin, disability or other characteristics protected by law.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Workable (global search)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Workable (global search)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Workable (global search)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.